Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdate' = '"%WINDIR%\Temp\svchost.exe"'
- %TEMP%\p886046.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\p886046.exe.log
- %TEMP%\p886046.exe
- '<LOCALNET_GATEWAY>':4444
- '%TEMP%\p886046.exe'